statamic/cms is vulnerable to Missing Authorization
65
Medium Risk
A Control Panel navigation endpoint does not verify that the caller is authorized to view the entries it returns. An authenticated Control Panel user can use the endpoint to read entry content and custom field values from any collection, including unpublished entries, that they otherwise lack permission to view. No data can be modified through this endpoint. The fix adds authorization checks so only entries the user may view are returned.
You are affected if you are using a version that falls within the vulnerable range and authenticated Control Panel users can call the navigation endpoint to read entries they are not permitted to view.
statamic/cms is vulnerable to Missing Authorization in versions 0.0.1 - 5.74.0 and 6.0.0 - 6.23.0.
Upgrade the statamic/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant